
The IP Deskphone can download a PKCS#12 file from the provisioning server. The
provisioning configuration file (for example, 11xxe.cfg), contains the [DEV_CERT] section
where the FILENAME attribute points to the PKCS#12 file name. The file name must include
the * symbol which is substituted with the IP Deskphone MAC address to allow the definition
of unique filenames for the PKCS#12 files containing the device certificates for each IP
Deskphone.
The following is an example of the [DEV_CERT] section:
Figure 28: Example of the [DEV_CERT] section
The administrator is responsible for creating the PKCS#12 file with the required device
certificate associated with the private key of the device certificate. The PKCS#12 file must be
in Distinguished Encoding Rules (DER) or BER format. If you are creating the certificate for
the first time, you must mark the private key of the certificate as exportable. If you export a
certificate to a PKCS#12 file, you must enter a password.
Important:
The PKCS#12 password cannot exceed 12 characters in length and must include only
characters that you can enter on the IP Deskphone. These characters include all numbers,
upper and lower case letters, and the following special characters: _ - . ! @ $ % & + : ^
Installing a device certificate using PKCS 12
The high level sequence of procedures for installing a device certificate using a PKCS#12 file
is as follows:
1. The PROFILE Index can range from 1 to the maximum number of supported Device
Certificate Profiles (DCP) for the IP Deskphone type.
Configure the DCP for the specified index for a PKCS#12 downloaded certificate,
otherwise the file is rejected. By default, profile 1 is configured for SCEP and all
other profiles are configured for PKCS#12.
2. The IP Deskphone checks the version in the [DEV_CERT] section against the
version stored in the specified PROFILE. If the version in the specified profile is
missing or is older, the device certificate file is downloaded. The profile index is 1.
3. Download the file.
4. Enter the PKCS#12 protected password.
Certificate-based authentication
210 SIP Software for Avaya 1200 Series IP Deskphones-Administration January 2012
Comentarios a estos manuales